Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 306 231

Количество 306 231

github логотип

GHSA-23j3-qh8r-rpx6

больше 3 лет назад

Cross-site scripting vulnerability in L-Forum 2.40 and earlier, when the "Enable HTML in messages" option is off, allows remote attackers to insert arbitrary script or HTML via message fields including (1) From, (2) E-Mail, and (3) Subject.

EPSS: Низкий
github логотип

GHSA-23j2-8hh8-295f

10 дней назад

In the Linux kernel, the following vulnerability has been resolved: scsi: hpsa: Fix possible memory leak in hpsa_init_one() The hpda_alloc_ctlr_info() allocates h and its field reply_map. However, in hpsa_init_one(), if alloc_percpu() failed, the hpsa_init_one() jumps to clean1 directly, which frees h and leaks the h->reply_map. Fix by calling hpda_free_ctlr_info() to release h->replay_map and h instead free h directly.

EPSS: Низкий
github логотип

GHSA-23hx-rv96-mjqx

больше 3 лет назад

IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

EPSS: Низкий
github логотип

GHSA-23hx-gmq6-vwxq

больше 3 лет назад

Belkin LINKSYS RE6500 devices before 1.0.11.001 allow remote authenticated users to execute arbitrary commands via goform/systemCommand?command= in conjunction with the goform/pingstart program.

EPSS: Низкий
github логотип

GHSA-23hw-vp6g-7987

7 месяцев назад

A stored Cross-site Scripting (XSS) vulnerability affecting Service Items Management in Service Process Engineer from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-23hv-mwm6-g8jf

4 месяца назад

Apache Tomcat Session Fixation vulnerability

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-23hv-h2r7-ggj5

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ImageRecycle ImageRecycle pdf & image compression allows Reflected XSS.This issue affects ImageRecycle pdf & image compression: from n/a through 3.1.16.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-23hv-gjhm-8vrh

3 месяца назад

A vulnerability was identified in D-Link DIR-823X 250416. This affects the function uci_set of the file /goform/set_wifi_blacklists. Such manipulation leads to command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-23hr-frj7-4j88

больше 3 лет назад

SQL injection vulnerability in forum/modules/gallery/post.php in Invision Gallery 2.0.7 allows remote attackers to cause a denial of service and possibly have other impacts, as demonstrated using a "SELECT BENCHMARK" statement in the img parameter in a doaddcomment operation in index.php.

EPSS: Низкий
github логотип

GHSA-23hq-37gx-cxwv

больше 3 лет назад

drm.c in Linux kernel 2.6.10 to 2.6.13 creates a debug file in sysfs with world-readable and world-writable permissions, which allows local users to enable DRM debugging and obtain sensitive information.

EPSS: Низкий
github логотип

GHSA-23hm-7w47-xw72

почти 4 года назад

Out of bounds read in Tensorflow

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-23hh-8f6m-x9cp

больше 3 лет назад

ar web content manager (AWCM) 2.2 does not restrict the number of comment records that can be submitted through HTTP requests, which allows remote attackers to cause a denial of service (disk consumption) via the coment parameter to (1) show_video.php or (2) topic.php.

EPSS: Низкий
github логотип

GHSA-23hh-7w49-jrpv

около 1 месяца назад

A security vulnerability has been detected in SimStudioAI sim up to ed9b9ad83f1a7c61f4392787fb51837d34eeb0af. This affects an unknown part. The manipulation of the argument filePath leads to path traversal. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The identifier of the patch is 45372aece5e05e04b417442417416a52e90ba174. To fix this issue, it is recommended to deploy a patch.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-23hh-6pg2-wjj5

больше 3 лет назад

An issue was discovered in OTCMS 3.61. XSS exists in admin/users.php via these parameters: dataTypeCN dataMode dataModeStr.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-23hg-53q6-hqfg

3 месяца назад

ImageMagick BlobStream Forward-Seek Under-Allocation

CVSS3: 3.8
EPSS: Низкий
github логотип

GHSA-23hf-jhww-867g

больше 3 лет назад

The Network Lock Manager (NLM) protocol implementation in the NFS client functionality in the Linux kernel before 3.0 allows local users to cause a denial of service (system hang) via a LOCK_UN flock system call.

EPSS: Низкий
github логотип

GHSA-23hc-wwmg-vgj2

больше 3 лет назад

SQL injection vulnerability in articles\articles_funcs.php in phpCOIN 1.2.2 allows remote attackers to modify SQL syntax and possibly execute SQL in limited circumstances via the rec_next parameter. NOTE: the original disclosure suggests that command injection is not feasible because the injection occurs after an "ORDER BY" clause, but it is likely that this bug could result in an error message path disclosure due to a syntax error, in some environments. Therefore this is an exposure and should be included in CVE.

EPSS: Низкий
github логотип

GHSA-23hc-w3jx-2m5j

больше 3 лет назад

CommonName Toolbar 3.5.2.0 sends unqualified domain name requests to the CommonName organization and possibly other web servers for name resolution, which allows those organizations to obtain internal server names.

EPSS: Низкий
github логотип

GHSA-23hc-gf5p-jq23

около 2 месяцев назад

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AmentoTech Workreap (theme's plugin) workreap allows Path Traversal.This issue affects Workreap (theme's plugin): from n/a through <= 3.3.5.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-23h9-xj7q-3m7r

11 месяцев назад

The issue was addressed with improved access restrictions to the file system. This issue is fixed in macOS Sequoia 15.3, Safari 18.3, iOS 18.3 and iPadOS 18.3, visionOS 2.3. A maliciously crafted webpage may be able to fingerprint the user.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-23j3-qh8r-rpx6

Cross-site scripting vulnerability in L-Forum 2.40 and earlier, when the "Enable HTML in messages" option is off, allows remote attackers to insert arbitrary script or HTML via message fields including (1) From, (2) E-Mail, and (3) Subject.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-23j2-8hh8-295f

In the Linux kernel, the following vulnerability has been resolved: scsi: hpsa: Fix possible memory leak in hpsa_init_one() The hpda_alloc_ctlr_info() allocates h and its field reply_map. However, in hpsa_init_one(), if alloc_percpu() failed, the hpsa_init_one() jumps to clean1 directly, which frees h and leaks the h->reply_map. Fix by calling hpda_free_ctlr_info() to release h->replay_map and h instead free h directly.

0%
Низкий
10 дней назад
github логотип
GHSA-23hx-rv96-mjqx

IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-23hx-gmq6-vwxq

Belkin LINKSYS RE6500 devices before 1.0.11.001 allow remote authenticated users to execute arbitrary commands via goform/systemCommand?command= in conjunction with the goform/pingstart program.

4%
Низкий
больше 3 лет назад
github логотип
GHSA-23hw-vp6g-7987

A stored Cross-site Scripting (XSS) vulnerability affecting Service Items Management in Service Process Engineer from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.

CVSS3: 8.7
0%
Низкий
7 месяцев назад
github логотип
GHSA-23hv-mwm6-g8jf

Apache Tomcat Session Fixation vulnerability

CVSS3: 6.5
0%
Низкий
4 месяца назад
github логотип
GHSA-23hv-h2r7-ggj5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ImageRecycle ImageRecycle pdf & image compression allows Reflected XSS.This issue affects ImageRecycle pdf & image compression: from n/a through 3.1.16.

CVSS3: 7.1
0%
Низкий
около 1 года назад
github логотип
GHSA-23hv-gjhm-8vrh

A vulnerability was identified in D-Link DIR-823X 250416. This affects the function uci_set of the file /goform/set_wifi_blacklists. Such manipulation leads to command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

CVSS3: 6.3
0%
Низкий
3 месяца назад
github логотип
GHSA-23hr-frj7-4j88

SQL injection vulnerability in forum/modules/gallery/post.php in Invision Gallery 2.0.7 allows remote attackers to cause a denial of service and possibly have other impacts, as demonstrated using a "SELECT BENCHMARK" statement in the img parameter in a doaddcomment operation in index.php.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-23hq-37gx-cxwv

drm.c in Linux kernel 2.6.10 to 2.6.13 creates a debug file in sysfs with world-readable and world-writable permissions, which allows local users to enable DRM debugging and obtain sensitive information.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-23hm-7w47-xw72

Out of bounds read in Tensorflow

CVSS3: 8.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-23hh-8f6m-x9cp

ar web content manager (AWCM) 2.2 does not restrict the number of comment records that can be submitted through HTTP requests, which allows remote attackers to cause a denial of service (disk consumption) via the coment parameter to (1) show_video.php or (2) topic.php.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-23hh-7w49-jrpv

A security vulnerability has been detected in SimStudioAI sim up to ed9b9ad83f1a7c61f4392787fb51837d34eeb0af. This affects an unknown part. The manipulation of the argument filePath leads to path traversal. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The identifier of the patch is 45372aece5e05e04b417442417416a52e90ba174. To fix this issue, it is recommended to deploy a patch.

CVSS3: 8.1
0%
Низкий
около 1 месяца назад
github логотип
GHSA-23hh-6pg2-wjj5

An issue was discovered in OTCMS 3.61. XSS exists in admin/users.php via these parameters: dataTypeCN dataMode dataModeStr.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-23hg-53q6-hqfg

ImageMagick BlobStream Forward-Seek Under-Allocation

CVSS3: 3.8
0%
Низкий
3 месяца назад
github логотип
GHSA-23hf-jhww-867g

The Network Lock Manager (NLM) protocol implementation in the NFS client functionality in the Linux kernel before 3.0 allows local users to cause a denial of service (system hang) via a LOCK_UN flock system call.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-23hc-wwmg-vgj2

SQL injection vulnerability in articles\articles_funcs.php in phpCOIN 1.2.2 allows remote attackers to modify SQL syntax and possibly execute SQL in limited circumstances via the rec_next parameter. NOTE: the original disclosure suggests that command injection is not feasible because the injection occurs after an "ORDER BY" clause, but it is likely that this bug could result in an error message path disclosure due to a syntax error, in some environments. Therefore this is an exposure and should be included in CVE.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-23hc-w3jx-2m5j

CommonName Toolbar 3.5.2.0 sends unqualified domain name requests to the CommonName organization and possibly other web servers for name resolution, which allows those organizations to obtain internal server names.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-23hc-gf5p-jq23

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AmentoTech Workreap (theme's plugin) workreap allows Path Traversal.This issue affects Workreap (theme's plugin): from n/a through <= 3.3.5.

CVSS3: 7.6
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-23h9-xj7q-3m7r

The issue was addressed with improved access restrictions to the file system. This issue is fixed in macOS Sequoia 15.3, Safari 18.3, iOS 18.3 and iPadOS 18.3, visionOS 2.3. A maliciously crafted webpage may be able to fingerprint the user.

CVSS3: 6.5
0%
Низкий
11 месяцев назад

Уязвимостей на страницу